TEMP2687100.DLL – Backdoor Farfli

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

TEMP2687100.DLL – Backdoor Farfli removal

FileMD5Virus Alias
TEMP2687100.DLL 9d470571584989e860040f3b21f7f590 Backdoor Farfli
TEMP2687100.DLL 9d470571584989e860040f3b21f7f590 Trojan Generic
TEMP2687100.DLL 9d470571584989e860040f3b21f7f590 Trojan Eldorado
TEMP2687100.DLL 9d470571584989e860040f3b21f7f590 Trojan Downloader
TEMP2687100.DLL 9d470571584989e860040f3b21f7f590 Trojan Magania

TEMP2687100.DLL size: 110592 bytes
TEMP2687100.DLL hash: 9D470571584989E860040F3B21F7F590

Created files:

C:\windows\system32\drivers\gui.sys
C:\windows\system32\Rnmeqtte.dll
C:\windows\temp2687100.dll

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\McAfee Network Agent\Type: 10010000
HKLM\System\CurrentControlSet\Services\McAfee Network Agent\Start: 02000000
HKLM\System\CurrentControlSet\Services\McAfee Network Agent\DisplayName: McAfee Network Agent
HKLM\System\CurrentControlSet\Services\McAfee Network Agent\ImagePath: %SystemRoot%\System32\svchost.exe -k imgsvc

Detected by UnHackMe:

TEMP2687100.DLL
Default location: %TEMP%2687100.DLL

Dropper information:
MD5: 2d354f129cda59fcddf0d30d97db18cf
File size: 163840 bytes

Leave a Reply